HomeTopics 1Advanced Persistent ThreatVMware vCenter Under Active Attack: 361 Systems Compromised in Global APT Campaign

VMware vCenter Under Active Attack: 361 Systems Compromised in Global APT Campaign

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

Threat actors are actively exploiting critical vulnerabilities in VMware vCenter Server instances worldwide, leaving enterprise virtualization environments exposed to complete administrative takeover. Security researchers have already identified at least 361 compromised systems in an ongoing global APT campaign forcing organizations to patch immediately or face total infrastructure compromise.

Cybersecurity researchers are tracking an aggressive exploitation campaign targeting VMware vCenter servers that has already compromised at least 361 unique IP addresses across 47 countries. The attacks, which began just five days after Broadcom publicly disclosed CVE-2026-59310, appear to be the work of a sophisticated advanced persistent threat (APT) actor using an open-source reverse-shell framework called reverse_ssh to maintain persistent access.

Key details:

  • Vulnerability: CVE-2026-59310 (CVSS 9.8) critical directory traversal in vCenter Syslog server
  • Timeline: Disclosed July 29, first attacks observed August 3, peak activity August 4
  • Victims: 361 unique IPs, with Germany, US, Turkey, Iran, and France most affected
  • Access method: Reverse SSH connections bypassing inbound firewall controls
  • Urgency: No workaround available patching is the only option

Understanding CVE-2026-59310

The vulnerability at the center of this campaign is a directory-traversal flaw in VMware vCenter’s Syslog server, awarded the maximum CVSS score of 9.8. What makes this particularly concerning is that an attacker with network access to vCenter can exploit it to execute arbitrary code essentially taking control of the system.

Broadcom has confirmed that no workaround exists for this vulnerability. Organizations operating VMware vCenter must patch immediately using one of the following fixed releases:

  • vCenter 9.1: 9.1.0.0300
  • vCenter 9.0: 9.0.2.0100
  • vCenter 8.0: 8.0 U3k or 8.0 U2f (depending on branch)

For detailed installation instructions, organizations should consult Broadcom advisory VMSA-2026-0006.1.

A Narrow Window from Disclosure to Exploitation

Perhaps the most alarming aspect of this campaign is the speed at which attackers moved. Broadcom published the advisory on July 29. The first compromised systems connected to attacker infrastructure just five calendar days later, on August 3.

The campaign peaked the following day, with 151 additional victim IPs observed. By August 5 – less than a week after disclosure – approximately 95% of the 361 identified victims had already been compromised.

Germany, the United States, Turkey, Iran, and France account for just over half of all observed victim infrastructure, with 185 of the 361 identified IP addresses concentrated in these five countries.

QUIRSO’s Threat Research team, which is tracking the campaign, notes that while attackers may have had prior knowledge of the vulnerability, the strong temporal correlation suggests public disclosure served as the trigger for the mass exploitation campaign.

The Reverse SSH Connection

Following successful compromise, attackers deploy reverse_ssh an open-source SSH-based reverse-shell framework originally designed for legitimate penetration testing. Its features include automatic connect-back functionality, SSH port forwarding, file transfer, and remote shell management.

Why is reverse SSH particularly dangerous? Because it establishes an outbound connection from the compromised system back to the attacker’s infrastructure. This cleverly bypasses security controls primarily designed to block unsolicited inbound access, making detection significantly more challenging.

Security teams should note that the presence of reverse_ssh alone does not confirm malicious activity it is a legitimate security tool. However, when observed alongside unauthorized installation, unexpected outbound connections, or execution on a vulnerable vCenter appliance, it becomes a high-priority indicator requiring immediate investigation.

Global Impact and Why It Matters

vCenter serves as the central management platform for VMware virtualized environments, often running critical infrastructure, data centers, and cloud operations. A compromise at this level gives attackers:

  1. Unrestricted access to virtual machines and hosted applications
  2. Visibility into internal network architecture
  3. Lateral movement capabilities across the entire virtualized environment
  4. Persistent control through stealthy reverse connections

For organizations in the Middle East and Africa, this threat demands immediate attention. The region has seen rapid digital transformation and cloud adoption, with many financial institutions, telecommunications providers, and government entities relying heavily on VMware virtualization. The combination of limited patching windows and constrained cybersecurity resources makes these organizations particularly vulnerable to fast-moving campaigns like this one.

Expert Commentary

Yannick KPAKI-EMILE, Manager Security Capabilities & RSSI at Orange Services, emphasized the importance of proactive defense in a recent interview with CyberCory.com:

“Today, the question is no longer just about how to protect ourselves, but also about how an attacker could bypass us – and how we can detect them before they achieve their objectives. The key is combining technology, human expertise, and processes that can evolve rapidly against emerging threats.”

His perspective underscores the challenge posed by campaigns like this one, where attackers exploit the gap between disclosure and patching to gain footholds.

What vCenter Operators Must Do Now

Immediate Actions

  1. Review Broadcom Security Advisory VMSA-2026-0006.1 immediately
  2. Identify your vCenter version and determine the applicable fixed release
  3. Apply the vendor update without delay no workaround exists
  4. Scan your environment for systems with unexpected outbound SSH connections
  5. Check for unauthorized reverse_ssh binaries on vCenter systems

Investigation Indicators

Security teams should investigate:

  • Unexpected outbound SSH connections from vCenter servers
  • Presence of reverse_ssh binaries (treat as investigative lead, not definitive proof)
  • Unauthorized scheduled tasks or cron jobs
  • Unexplained file modifications in vCenter directories
  • Systems connecting to unusual external IP addresses (QUIRSO has published detection content via GitHub)

Long-term Security Measures

  1. Adopt a Zero Trust approach as Yannick KPAKI-EMILE also noted in his interview, “Trust doesn’t exclude control; this philosophy must be applied at all levels of our organizations”
  2. Implement network segmentation to limit vCenter exposure
  3. Deploy robust monitoring for outbound connections and anomalous SSH traffic
  4. Conduct regular vulnerability assessments to identify internet-exposed management interfaces
  5. Invest in incident response capabilities organizations can contact QUIRSO GmbH at research@quirso.de for compromise assessment support

Detection Support for Security Teams

The QUIRSO Threat Research Team has released a generic YARA rule for identifying reverse_ssh builds, available through their GitHub account. This rule is designed to support threat hunting activities, though matches should be treated as investigative leads requiring correlation with other signs of compromise.

Important: Attacker-specific indicators and additional detection content are being withheld temporarily, coordinated with law enforcement to avoid interfering with ongoing investigations.

What’s Next

QUIRSO’s Threat Research team continues to analyze this campaign, with a detailed follow-up publication expected to examine:

  • Attacker tradecraft and infrastructure
  • Persistence mechanisms in greater depth
  • Post-exploitation activity observed during intrusions
  • Additional detection and investigation guidance

A Broader Warning for the Industry

This campaign serves as yet another reminder of the growing sophistication and speed of modern cyber threats. The five-day window from disclosure to exploitation is concerning and it reflects a broader trend where attackers weaponize vulnerabilities faster than many organizations can patch.

For security teams, the lesson is clear: patch management processes must be agile enough to respond to critical CVEs within days, not weeks. For organizations still operating with manual or slow-moving patching cycles, this should be a wake-up call.

The threat is here, and it is accelerating. The only question is whether your organization will be ready when attackers come knocking.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img